Lucene search

K
cve[email protected]CVE-2011-3056
HistoryMar 22, 2012 - 4:55 p.m.

CVE-2011-3056

2012-03-2216:55:01
CWE-346
web.nvd.nist.gov
44
cve-2011-3056
google chrome
same origin policy
magic iframe
security vulnerability
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.4%

Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a “magic iframe.”

Affected configurations

NVD
Node
googlechromeRange<17.0.963.83
Node
opensuseopensuseMatch12.1
Node
applesafariRange<5.1.7
OR
appleiphone_osRange<5.1.1

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.4%